PermissionDefinitions Object
Relationships
graph LR
PermissionDefinitions -->|"account"| Accounts
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
Permitted actions with wildcards intact, e.g. 's3:' or 'ec2:Describe' -- never expanded. An empty array means the document grants nothing; null means the document could not be read (see unreadable_fields).
Total assignments, where the provider exposes a single combined number.
How many principals this definition is attached to as a grant, kept separate from permissions_boundary_usage_count (a restriction, not a grant).
When Truto read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider-supplied timestamp.
When the definition was created.
The provider's own identifier for the policy or role definition.
Explicitly denied actions, with wildcards intact.
Whether any statement grants a bare action wildcard. Derived.
Whether any statement applies to a bare resource wildcard. Derived.
Whether the customer authored this, as opposed to a provider-supplied built-in.
The policy or role name as the provider names it.
The provider's own type string, unmodified -- for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
Actions under a NotAction clause, kept separate from allowed_actions. Combined with Allow, this permits everything EXCEPT these actions -- the inverse of a normal action list.
Resources under a NotResource clause. Combined with Allow, this excludes these resources rather than including them.
How many principals use this definition as a permissions boundary -- a restriction, not a grant.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier, verbatim -- a full ARN, resource id, or self-link. Never truncated or normalised. Use it to find the object in the provider's console.
The provider's raw policy document as a string, in its native encoding. AWS IAM documents are URL-encoded (RFC 3986); Organizations and Identity Center inline documents are plain JSON.
Where the object is located. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider gives none, the collector's queried region is used instead and flagged in unreadable_fields.
Raw data returned from the remote API call.
The resources the permissions apply to, with wildcards intact.
Key-value pairs exactly as the customer set them -- no case folding, key/value normalisation, or merging across providers. An empty object means no tags; unreadable tags appear in unreadable_fields instead.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Additional detail on the reason, when there is any.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the definition was last modified.